smcenroe
02-20-2008, 11:27 AM
I have a client that stores no cardholder data in the POS application. Is it really necessary to do all the granular logging of the system?
jbhall56
02-25-2008, 09:16 PM
Yes.
The reason is for the forensic value it provides later on when something goes wrong.
As an example, I have a client that had an interesting situation a couple of years back where teenage cashiers were issuing refunds to their credit cards when they were not checking out customers. These teenagers would go out on a buying spree for a new wardrobe and buy a lot of clothes at the Gap, Limited, etc. Rather than pay the bill, they would issue refunds in amounts less than $25 to $35 to avoid any scrutiny by the company's fraud department. Granted it took a while to refund a couple of hundred dollars. But what's easier, getting your employer to pay for your new clothes or having to work overtime to pay for them and not have time to go out to show them off? Since they did not have logging on, the POS system they were using was not recording application activity for later review. It took MasterCard about 9 months to identify the problem and notify the retailer that excessive refunds for card accounts never or only occasionally used on their system for purchases were occurring and to figure out what was going on. Had logging been enabled, as it is now, they would have been able to at least identify an excessive number of refunds at particular outlets, thus triggering some sort of further investigation.
vBulletin® v3.7.4, Copyright ©2000-2010, Jelsoft Enterprises Ltd.